Description
[Sagerunex](https://attack.mitre.org/software/S1210) is a malware family exclusively associated with [Lotus Blossom](https://attack.mitre.org/groups/G0030) operations, with variants existing since at least 2016. Variations of [Sagerunex](https://attack.mitre.org/software/S1210) leverage non-traditional command and control mechanisms such as various web services.(Citation: Symantec Bilbug 2022)(Citation: Cisco LotusBlossom 2025)
External References
Techniques Used by This Malware
- T1016 — System Network Configuration Discovery
- T1027.002 — Software Packing
- T1027.013 — Encrypted/Encoded File
- T1041 — Exfiltration Over C2 Channel
- T1055.001 — Dynamic-link Library Injection
- T1057 — Process Discovery
- T1071.001 — Web Protocols
- T1074.001 — Local Data Staging
- T1082 — System Information Discovery
- T1090 — Proxy
- T1102.002 — Bidirectional Communication
- T1102.003 — One-Way Communication
- T1106 — Native API
- T1134 — Access Token Manipulation
- T1140 — Deobfuscate/Decode Files or Information
- T1480 — Execution Guardrails
- T1560.001 — Archive via Utility
- T1573.002 — Asymmetric Cryptography